feat: harden self-managed reconciliation

This commit is contained in:
2026-09-05 10:17:55 +00:00 Unverified
parent 8e9d207915
commit 321f4e807a
40 changed files with 4977 additions and 404 deletions
+36 -1
View File
@@ -94,7 +94,9 @@ describe("kuber config", () => {
{ services: { app: { build: "." } } },
process.cwd(),
{},
{ app: `registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}` },
{
app: `registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}`,
},
);
const deployment = resources.find(
(resource) => resource.kind === "Deployment",
@@ -103,6 +105,39 @@ describe("kuber config", () => {
`registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}`,
);
});
test("scopes the server RBAC self-management rules", async () => {
const config = await loadConfig(process.cwd());
const resources: any[] = [];
await config.postRender?.(resources, {
cwd: process.cwd(),
project: "kuber-system",
composeFile: "compose.yml",
});
const role = resources.find((resource) => resource.kind === "Role");
const manager = resources.find(
(resource) => resource.kind === "ClusterRole",
);
expect(role.rules).toContainEqual({
apiGroups: [""],
resources: ["serviceaccounts"],
resourceNames: ["kuber-server"],
verbs: ["get", "update", "patch"],
});
expect(role.rules).toContainEqual({
apiGroups: ["rbac.authorization.k8s.io"],
resources: ["roles", "rolebindings"],
resourceNames: ["kuber-server-auth"],
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"],
});
expect(manager.rules).toContainEqual({
apiGroups: ["rbac.authorization.k8s.io"],
resources: ["clusterroles", "clusterrolebindings"],
resourceNames: ["kuber-server-manager"],
verbs: ["get", "update", "patch"],
});
});
});
describe("global config argument", () => {